is this secure by default in rails yet? i find it surprising that these techniques are promoted at the same time vulnerabilities are being publicly disclosed:
https://groups.google.com/d/msg/rubyonrails-core/rwzM8MKJbKU...
https://groups.google.com/d/msg/rubyonrails-core/rwzM8MKJbKU...
See http://weblog.rubyonrails.org/2011/2/8/csrf-protection-bypas...
I was under the impression that trying to validate that was ultimately as fragile as checking the user-agent string...